Chat becomes permanently unresponsive after cybersecurity safety message
What version of the Codex App are you using (From “About Codex” dialog)?
26.805.11740
What subscription do you have?
Chatgpt Plus
What platform is your computer?
Windows
What issue are you seeing?
Description
While using Codex for an authorized cybersecurity competition involving vulnerability analysis of an APK, I received the message:
This content can't be shown. We take extra caution with cybersecurity requests.
After this message appeared, the affected chat stopped responding entirely. Even harmless messages such as “hi” received no response.
I understand that the original cybersecurity request may trigger a safety safeguard. The suspected bug is that the entire chat remained unusable afterward, including for unrelated and harmless prompts.
Environment
- Application: ChatGPT desktop app with Codex
- Operating system: Windows [add Windows version]
- App version: [add version, or write “Unknown”]
- Model: GPT-5.6 Sol
- Reasoning level: Medium
- Approximate occurrence time: [date and time, including timezone]
- Affected chat: “Prepare for Kratosid hackathon”
Steps to reproduce
- Open a Codex chat in the ChatGPT desktop app.
- Discuss authorized APK vulnerability research for a cybersecurity competition.
- Trigger the “This content can't be shown” cybersecurity notice.
- Send an unrelated harmless message such as “hi.”
- Observe that no response is produced and the chat remains unusable.
<img width="1600" height="885" alt="Image" src="https://github.com/user-attachments/assets/53a2d195-1b1c-4117-ac73-7a15e5bd06fe" />
Actual behaviour
The affected chat stopped responding to every subsequent message, including harmless messages.
What steps can reproduce the bug?
Reproducibility
Occurred: [once / multiple times]
New chats work: [yes / no]
Restarting the app fixes it: [yes / no / not tested]
Changing the model fixes it: [yes / no / not tested]
What is the expected behavior?
Only the request that triggered the cybersecurity safeguard should be blocked or rerouted. The user should still be able to continue the conversation with harmless requests, or the application should clearly explain any account/session restriction.
Additional information
I submitted private in-product feedback containing the affected session.
A screenshot showing the cybersecurity message and unanswered “hi” message is attached.
This is being reported as a product/safety-classifier false-positive or stuck-session bug. I have not established a security exploit.
1 Comment
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action